PT-2021-4655 · Cisco · Cisco Ios Xe

Published

2021-09-22

·

Updated

2021-10-05

·

CVE-2021-1625

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software (affected versions not specified)
Description The issue is related to the Zone-Based Policy Firewall feature of Cisco IOS XE Software, where insufficient access control restrictions when configuring Unified Threat Defense (UTD) or Application Quality of Experience (AppQoE) can be exploited. An unauthenticated, remote attacker could send ICMP or UDP packets to bypass security restrictions, potentially allowing traffic to be incorrectly classified or dropped. This could also result in incorrect reporting figures produced by high-speed logging (HSL).
Recommendations For Cisco IOS XE Software, update to a version that includes the fix for this issue, as software updates have been released by Cisco to address this vulnerability. As a temporary workaround, consider restricting access to the Zone-Based Policy Firewall feature until a patch is available. Avoid using the Unified Threat Defense (UTD) or Application Quality of Experience (AppQoE) configurations in the Zone-Based Policy Firewall until the issue is resolved.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05348
CVE-2021-1625

Affected Products

Cisco Ios Xe